Ransomware group
Cactus ransomware: victims and leak site activity
The Cactus ransomware group has listed 248 victims on its leak site since July 2023; its latest post is from 21 March 2025. Most affected countries: United States, Canada and United Kingdom. Most targeted sector: Manufacturing.
About Cactus
The CACTUS ransomware is said to have emerged around March 2023. The group became known for exploiting vulnerabilities to gain initial access and maintain a presence within the organization's infrastructure. There is little known information about the ransomware group, except that it emerged on the mentioned date and, following encryption, a text file named 'cAcTuS.readme.txt' would be created. Additionally, encrypted files were altered to the '.cts1' extension, and data exfiltration and victim extortion were conducted through the use of the service known as Tox. Source: https://github.com/crocodyli/ThreatActors-TTPs
Most targeted countries
- United States 105
- Canada 18
- United Kingdom 15
- France 9
- Spain 6
- Germany 5
- Netherlands 5
- Australia 4
- Belgium 4
- Denmark 4
Most targeted sectors
- Manufacturing 55
- Professional Services 51
- Technology 41
- Retail & E-Commerce 33
- Agriculture and Food Production 16
- Transportation 13
- Healthcare 11
- Financial Services 10
- Energy & Utilities 4
- Hospitality 4